There are 2 repositories under bughunter topic.
LazyHunter is an automated reconnaissance tool designed for bug hunters, leveraging Shodan's InternetDB and CVEDB APIs
Collection of XSS Payloads for fun and profit
Docker Remote API Scanner and Exploit
Enhanced BurpGPT 是一个强大的 Burp Suite 插件。通过分析指定的 HTTP 请求和响应,帮助安全测试人员更快速地发现潜在的安全漏洞。
This repository stores various roadmap(Mindmaps) for bug bounty Hunter, pentester, offensive(red team), defensive(blue team) and security Professional people
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
🔍 A simple tool to obtain long lists of ips from domains using goroutines
Red teaming is an attack technique used in cyber security to test how an organisation would respond to a genuine cyber attack. It is done through an Ethical Hacking team or similar offensive security team.
This is a tool for bug hunters
Priv8 Tools Software Mass Dork Auto Exploit.
Web application penetration testing
This program provides a Graphical User Interface (GUI) to convert images into "invisible" images that can bypass Instagram’s visibility on the Android app. The bug works exclusively on the Instagram Android app and this tool operates on both Linux and Windows platforms.
ReconHound is a Python-based web reconnaissance tool designed for penetration testers, bug bounty hunters, and ethical hackers. It supports directory and file enumeration, subdomain enumeration, fuzzing, and virtual host (vhost) discovery.
WebScan is a Python-based tool designed to scan websites for sensitive information like IP addresses, vulnerabilities, SSL details, and other security-related insights. It helps users test website security and provides detailed results in a well-organized format using the rich library.
Sitemap Exporter is an extension for Burp Suite that lets you export items from the Site Map to files on your disk.
httpxUtilz is a basic tool for target information gathering and attack surface.
Web Application Bug Checklist
start to code for hack using swift for find vulnerabilities and report
**Automated archival scraping** for researchers, bughunters, and digital historians.
Hi, I’m Karan Vaniya, known in cybersecurity as Bitex (b1t3x0p). I’m an ethical hacker and bug bounty hunter, skilled in discovering hidden security flaws and protecting critical systems. I’ve earned a place in NASA’s Hall of Fame and am an Indian Book of Records holder
A highly automated and modular bug bounty reconnaissance toolkit integrating over 15 industry-standard tools for streamlined subdomain enumeration, vulnerability detection, and OSINT gathering. Designed for efficiency, scalability, and precision in real-world security assessments.
PwnFox is an extension for Burp Suite
Firego scans Firebase databases for public access vulnerabilities, and offers an optional takeover.
osgit is an open-source GitHub OSINT tool for security researchers, bug bounty hunters, and penetration testers. It helps extract subdomains and repository paths from GitHub to generate useful wordlists or fuzzing dictionaries.